{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,14]],"date-time":"2026-03-14T17:58:28Z","timestamp":1773511108205,"version":"3.50.1"},"publisher-location":"Cham","reference-count":33,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319986531","type":"print"},{"value":"9783319986548","type":"electronic"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-319-99136-8_3","type":"book-chapter","created":{"date-parts":[[2018,8,14]],"date-time":"2018-08-14T08:39:41Z","timestamp":1534235981000},"page":"47-66","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":9,"title":["Lumus: Dynamically Uncovering Evasive Android Applications"],"prefix":"10.1007","author":[{"given":"Vitor","family":"Afonso","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Anatoli","family":"Kalysch","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tilo","family":"M\u00fcller","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Daniela","family":"Oliveira","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Andr\u00e9","family":"Gr\u00e9gio","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Paulo L\u00edcio","family":"de Geus","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,8,15]]},"reference":[{"key":"3_CR1","doi-asserted-by":"crossref","unstructured":"Arp, D., Spreitzenbarth, M., H\u00fcbner, M., Gascon, H., Rieck, K.: DREBIN: effective and explainable detection of Android malware in your pocket. In: NDSS (2014)","DOI":"10.14722\/ndss.2014.23247"},{"key":"3_CR2","unstructured":"Balzarotti, D., Cova, M., Karlberger, C., Kirda, E., Kruegel, C., Vigna, G.: Efficient detection of split personalities in malware. In: NDSS (2010)"},{"key":"3_CR3","doi-asserted-by":"crossref","unstructured":"Busch, M., Protsenko, M., M\u00fcller, T.: A cloud-based compilation and hardening platform for Android apps. In: Proceedings of the 12th International Conference on Availability, Reliability and Security (ARES). SBA Research, Reggio Calabria (2017)","DOI":"10.1145\/3098954.3098959"},{"key":"3_CR4","doi-asserted-by":"crossref","unstructured":"Dresel, L., Protsenko, M., M\u00fcller, T.: Artist: the Android runtime instrumentation toolkit. In: Proceedings of the 11th International Conference on Availability, Reliability and Security (ARES). SBA Research, Salzburg (2016)","DOI":"10.1109\/ARES.2016.80"},{"key":"3_CR5","unstructured":"Elish, K.O., Yao, D., Ryder, B.G.: User-centric dependence analysis for identifying malicious mobile apps. In: MOST (2012)"},{"key":"3_CR6","doi-asserted-by":"crossref","unstructured":"Grace, M., Zhou, Y., Zhang, Q., Zou, S., Jiang, X.: Riskranker: scalable and accurate zero-day Android malware detection. In: MOBISYS (2012)","DOI":"10.1145\/2307636.2307663"},{"key":"3_CR7","doi-asserted-by":"crossref","unstructured":"Guan, L., Jia, S., Chen, B., Zhang, F., Luo, B., Lin, J., Liu, P., Xing, X., Xia, L.: Supporting transparent snapshot for bare-metal malware analysis on mobile devices. In: Proceedings of the 33rd ACSAC, pp. 339\u2013349. ACM (2017)","DOI":"10.1145\/3134600.3134647"},{"key":"3_CR8","doi-asserted-by":"crossref","unstructured":"Haupert, V., M\u00fcller, T.: On app-based matrix code authentication in online banking. In: Furnell, S., Mori, P., Camp, O. (eds.) Proceedings of the 4th International Conference on Information Systems Security and Privacy (ICISSP), pp. 149\u2013160. SciTePress, Funchal (2018)","DOI":"10.5220\/0006650501490160"},{"key":"3_CR9","doi-asserted-by":"crossref","unstructured":"Jing, Y., Zhao, Z., Ahn, G.J., Hu, H.: Morpheus: automatically generating heuristics to detect Android emulators. In: ACSAC (2014)","DOI":"10.1145\/2664243.2664250"},{"key":"3_CR10","doi-asserted-by":"crossref","unstructured":"Kalysch, A., G\u00f6tzfried, J., M\u00fcller, T.: VMAttack: deobfuscating virtualization-based packed binaries. In: Proceedings of the 12th International Conference on Availability, Reliability and Security, p. 2. ACM (2017)","DOI":"10.1145\/3098954.3098995"},{"key":"3_CR11","doi-asserted-by":"crossref","unstructured":"Kirat, D., Vigna, G.: MalGene: automatic extraction of malware analysis evasion signature. In: ACM CCS (2015)","DOI":"10.1145\/2810103.2813642"},{"key":"3_CR12","unstructured":"Kirat, D., Vigna, G., Kruegel, C.: BareCloud: bare-metal analysis-based evasive malware detection. In: USENIX Security (2014)"},{"key":"3_CR13","doi-asserted-by":"crossref","unstructured":"Kolbitsch, C., Kirda, E., Kruegel, C.: The power of procrastination: detection and mitigation of execution-stalling malicious code. In: ACM CCS (2011)","DOI":"10.1145\/2046707.2046740"},{"key":"3_CR14","unstructured":"Li, Y.: Droidbot (2012). http:\/\/honeynet.github.io\/droidbot\/"},{"key":"3_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"338","DOI":"10.1007\/978-3-642-23644-0_18","volume-title":"Recent Advances in Intrusion Detection","author":"M Lindorfer","year":"2011","unstructured":"Lindorfer, M., Kolbitsch, C., Milani Comparetti, P.: Detecting environment-sensitive malware. In: Sommer, R., Balzarotti, D., Maier, G. (eds.) RAID 2011. LNCS, vol. 6961, pp. 338\u2013357. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-23644-0_18"},{"key":"3_CR16","doi-asserted-by":"crossref","unstructured":"Lindorfer, M., Neugschwandtner, M., Weichselbaum, L., Fratantonio, Y., van der Veen, V., Platzer, C.: Andrubis - 1,000,000 apps later: a view on current Android malware behaviors. In: BADGERS (2014)","DOI":"10.1109\/BADGERS.2014.7"},{"key":"3_CR17","doi-asserted-by":"crossref","unstructured":"Maier, D., M\u00fcller, T., Protsenko, M.: Divide-and-conquer: why Android malware cannot be stopped. In: Proceedings of the 9th International Conference on Availability, Reliability and Security (ARES). SBA Research, Fribourg (2014)","DOI":"10.1109\/ARES.2014.12"},{"key":"3_CR18","unstructured":"Matenaar, F., Schulz, P.: Detecting Android sandboxes. http:\/\/www.dexlabs.org\/blog\/btdetect"},{"key":"3_CR19","doi-asserted-by":"crossref","unstructured":"Miramirkhani, N., Appini, M.P., Nikiforakis, N., Polychronakis, M.: Spotless sandboxes: evading malware analysis systems using wear-and-tear artifacts. In: IEEE Symposium on Security and Privacy (SP), pp. 1009\u20131024. IEEE (2017)","DOI":"10.1109\/SP.2017.42"},{"key":"3_CR20","doi-asserted-by":"crossref","unstructured":"Moser, A., Kruegel, C., Kirda, E.: Limits of static analysis for malware detection. In: ACSAC, pp. 421\u2013430. IEEE (2007)","DOI":"10.1109\/ACSAC.2007.21"},{"key":"3_CR21","doi-asserted-by":"crossref","unstructured":"Mutti, S., Fratantonio, Y., Bianchi, A., Invernizzi, L., Corbetta, J., Kirat, D., Kruegel, C., Vigna, G.: Baredroid: large-scale analysis of Android apps on real devices. In: ACSAC (2015)","DOI":"10.1145\/2818000.2818036"},{"key":"3_CR22","doi-asserted-by":"crossref","unstructured":"Petsas, T., Voyatzis, G., Athanasopoulos, E., Polychronakis, M., Ioannidis, S.: Rage against the virtual machine: hindering dynamic analysis of Android malware. In: EUROSEC (2014)","DOI":"10.1145\/2592791.2592796"},{"key":"3_CR23","doi-asserted-by":"crossref","unstructured":"Poeplau, S., Fratantonio, Y., Bianchi, A., Kruegel, C., Vigna, G.: Analyzing unsafe and malicious dynamic code loading in Android applications. In: NDSS (2014)","DOI":"10.14722\/ndss.2014.23328"},{"key":"3_CR24","unstructured":"Reina, A., Fattori, A., Cavallaro, L.: A system call-centric analysis and stimulation technique to automatically reconstruct Android malware behaviors. In: EUROSEC (2013)"},{"key":"3_CR25","series-title":"Advances in Intelligent Systems and Computing","doi-asserted-by":"publisher","first-page":"289","DOI":"10.1007\/978-3-642-33018-6_30","volume-title":"International Joint Conference CISIS\u201912-ICEUTE\u201912-SOCO\u201912 Special Sessions","author":"B Sanz","year":"2012","unstructured":"Sanz, B., Santos, I., Laorden, C., Ugarte-Pedrero, X., Bringas, P.G., Alvarez, G.: PUMA: permission usage to detect malware in Android. In: Herrero, \u00c1., et al. (eds.) CISIS\/ICEUTE\/SOCO 2012 Special Sessions. AISC, vol. 189, pp. 289\u2013298. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-33018-6_30"},{"key":"3_CR26","unstructured":"Spreitzenbarth, M.: The evil inside a droid - Android malware: past, present and future. In: Baltic Conference on Network Security & Forensics (2012)"},{"key":"3_CR27","doi-asserted-by":"crossref","unstructured":"Spreitzenbarth, M., Freiling, F., Echtler, F., Schreck, T., Hoffmann, J.: Mobile-sandbox: having a deeper look into Android applications. In: ACM SAC (2013)","DOI":"10.1145\/2480362.2480701"},{"key":"3_CR28","doi-asserted-by":"crossref","unstructured":"Su, X., Chuah, M., Tan, G.: Smartphone dual defense protection framework: detecting malicious applications in Android markets. In: International Conference on Mobile Ad-Hoc and Sensor Networks (2012)","DOI":"10.1109\/MSN.2012.43"},{"key":"3_CR29","doi-asserted-by":"crossref","unstructured":"Vidas, T., Christin, N.: Evading Android runtime analysis via sandbox detection. In: AsiaCCS (2014)","DOI":"10.1145\/2590296.2590325"},{"key":"3_CR30","doi-asserted-by":"crossref","unstructured":"Wu, D.J., Mao, C.H., Wei, T.E., Lee, H.M., Wu, K.P.: DroidMat: Android malware detection through manifest and API calls tracing. In: Asia JCIS (2012)","DOI":"10.1109\/AsiaJCIS.2012.18"},{"key":"3_CR31","doi-asserted-by":"crossref","unstructured":"Zheng, M., Sun, M., Lui, J.C.: Droid analytics: a signature based analytic system to collect, extract, analyze and associate Android malware. In: TrustCom (2013)","DOI":"10.1109\/TrustCom.2013.25"},{"key":"3_CR32","doi-asserted-by":"crossref","unstructured":"Zhou, Y., Jiang, X.: Dissecting Android malware: characterization and evolution. In: IEEE Symposium on Security & Privacy (2012)","DOI":"10.1109\/SP.2012.16"},{"key":"3_CR33","unstructured":"Zhou, Y., Wang, Z., Zhou, W., Jiang, X.: Hey, you, get off of my market: detecting malicious apps in official and alternative Android markets. In: NDSS (2012)"}],"container-title":["Lecture Notes in Computer Science","Developments in Language Theory"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-99136-8_3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,10,22]],"date-time":"2019-10-22T04:36:35Z","timestamp":1571718995000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-99136-8_3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783319986531","9783319986548"],"references-count":33,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-99136-8_3","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018]]}}}